Circumventing Deep Packet Inspection with Socat and Rot13
gist.github.com
Circumventing Deep Packet Inspection with Socat and Rot13
1–10 of 39 posts
Re: Circumventing Deep Packet Inspection with Socat and Rot13
#2Re: Circumventing Deep Packet Inspection with Socat and Rot13
#3Re: Circumventing Deep Packet Inspection with Socat and Rot13
#4So once the maintainers of the deep packet inspection software read this they will add rot13 to their code.
Re: Circumventing Deep Packet Inspection with Socat and Rot13
#5So once the maintainers of the deep packet inspection software read this they will add rot13 to their code.
Re: Circumventing Deep Packet Inspection with Socat and Rot13
#6Re: Circumventing Deep Packet Inspection with Socat and Rot13
#7So once the maintainers of the deep packet inspection software read this they will add rot13 to their code.
I'm not a security expert but we had those kind of measures at a previous job and AFAIK they are there so that a lazy employee (me) doesn't just skip configuring their tools to go through Artifactory out of laziness and introduce a supply chain vulnerability. If "pip install XYZ" just worked out of the box, how likely would it be that all 10k devs in your organization would bother configuring it to avoid PYPI?
Re: Circumventing Deep Packet Inspection with Socat and Rot13
#8So once the maintainers of the deep packet inspection software read this they will add rot13 to their code.
Which would slow down inspection by a factor of 25 if it were to check the whole keyspace.
Of course you could do rot2 - rot24 and all the other combinations. Is that were the factor 25 comes from?
The deep inspection needs to look only at the first couple of bytes of each new a TCP connection. So it's not that disrupting. After 2 bytes you can already skip for a vast fraction of other traffic.
Re: Circumventing Deep Packet Inspection with Socat and Rot13
#9Some companies mention in their employment contracts these type of circumvention activities, unless explicitly allowed, are a firing offense.
Re: Circumventing Deep Packet Inspection with Socat and Rot13
#10Earlier quoted context omitted.
Which would slow down inspection by a factor of 25 if it were to check the whole keyspace.
Where does the keyspace come from? rot13 has no keys. Of course you could do rot2 - rot24 and all the other combinations. Is that were the factor 25 comes from? The deep inspection needs to look only at the first couple of bytes of each new a TCP connection. So it's not that disrupting. After 2 bytes you can already skip for a vast fraction of other traffic.